当前位置:网站首页>Server and client dual authentication (2)
Server and client dual authentication (2)
2022-07-26 09:33:00 【Jack-ZOU】
The first is server-side authentication . Now the simpler way is to find a relevant certification service company , Follow the online tips , You can apply for a certificate , Some companies are free for low-level certificates , The certificate fees for advanced certificates range from several hundred to tens of thousands of yuan per year . I started from Wosign Applied for free DV certificate , Valid for three years , You can authenticate two domain names . The installation process is a little complicated , But it's easy to learn next time . Apply for the certificate knowledge server certificate , Prove to those who visit the website “ I am I ”, But it can't realize the client ( The visitor ) Certification of , That is not sure who can access . Asked the company , There is no clear answer .
The second way is not through the company , Issue certificates by software , You can issue certificates to the server , You can also send certificates to clients , Achieve two-way authentication . There is a German software called Xca, It's available online , After installing on the server , You can generate certificates . I tried , But it doesn't seem to achieve the expected effect . I don't doubt the usability of the software , It must be that some links in the operation process are not mastered .
The third way is Windows Self contained Active Directory Certificate Services (AD CS). The original operating system has a certificate service module , Only by default, it is not installed . use ADCS Issue a certificate , The method is simple , If it is used internally or within a certain range, there is no problem , But if it is for public use , What does this certificate mean when others don't know you , I don't know if it's credible . Third party companies , In fact, it acts as a witness 、 The role of notaries . So for those who provide public services , You may need a certificate from a third party .
How to install and use AD CS? It took me two weeks , Asked several customer service , It didn't solve the problem in my installation , Later, I consulted Microsoft engineers , finally “ reluctantly ” Finished configuration , It has been tested and can be used .
In the installation AD CS There will be all kinds of unexpected problems in the process . The problem I have is , Add server role AD CS after , The installation went well , But in the end, let me tell you , Installation successful , But the required service is not started . Then it can't be used normally . The error message prompted is as follows :Active Directory Certificate Services Setup failed , Error is as follows : The server service was not started 0x80070842(win32:2114).

I checked a lot of information , There is an introduction : Need to install file and printer sharing . installed , useless ! later , What Microsoft said , After installation AD CS Can't start itself . use services.msc Just start it up .
Install well ADCS after , stay IIS Can be seen in ,default web site Here is the original aspnet_clint Catalog , Also added a directory :CertEnroll, Two websites : CertSrv、ocsp.
The path is a : c:\Windows\system32\certsrv\certEnroll, c:\windows\system32\Certsrv\zh-cn, c:\windows\systemdate\ocsp, Default web site route : %systemDrive%\inetpub\wwwroot
For all that , After installation AD CS There are still many wonderful things . adopt web You can apply for a certificate , But on the server side and the client browser, visit the same website , The displayed content should be different . You can't successfully apply for a certificate on the client , You can only use the browser on the server side to web Way to operate . This problem continues to be studied .
Yesterday I did another experiment , Restore the system to the pure state , Only the operating system Windows2008R2, No other programs are installed . In this case, configure ADCS and IIS Surprisingly smooth . This reminds us of , If you need to enable Certificate Services , Arrange immediately after installing the operating system , It will go a lot better , Because there is no interference from other software .
How to use AD CS Two way Authentication ? There is a lot of information on the Internet , A period of time , I weighed my experiment and sent it to . To be continued .
边栏推荐
- 青少年软件编程等级考试标准解读_二级
- Audio and video knowledge
- M-ary number STR to n-ary number
- 登录模块用例编写
- asp. Net using redis cache
- Redis sentinel mode setup under Windows
- RMQ学习笔记
- Custom password input box, no rounded corners
- [shutter -- layout] detailed explanation of the use of align, center and padding
- V-for dynamically sets the SRC of img
猜你喜欢

使用openLayer画箭头

Basic use of ArcGIS 4
![[shutter -- layout] detailed explanation of the use of align, center and padding](/img/01/c588f75313580063cf32cc01677600.jpg)
[shutter -- layout] detailed explanation of the use of align, center and padding
![[Online deadlock analysis] by index_ Deadlock event caused by merge](/img/67/0a02ad248c3ab21d3240e12aa23313.png)
[Online deadlock analysis] by index_ Deadlock event caused by merge

会议OA项目(三)---我的会议(会议排座、送审)

配置ADCS后访问certsrv的问题

asp. Net using redis cache
![[MySQL] understand the important architecture of MySQL (I)](/img/89/5fb595b0112fac987626857b76f9a4.png)
[MySQL] understand the important architecture of MySQL (I)

CSV data file settings of JMeter configuration components

cocoapods的安装和使用
随机推荐
[Online deadlock analysis] by index_ Deadlock event caused by merge
设置视图动态图片
keepalived 实现mysql自动故障切换
Redis sentinel mode setup under Windows
Jmeter配置元件之CSV数据文件设置
JS 一行代码 获取数组最大值与最小值
E. Two Small Strings
Login module use case writing
高斯消元求解矩阵的逆(gauss)
登录模块用例编写
PHP一次请求生命周期
QT随手笔记(六)——更新界面、截图、文件对话框
arcgis的基本使用1
网站设计需要的基本知识
“互联网+”时代的现代医学
大二上第二周学习笔记
mysql5.7.25主从复制(单向)
配置ADCS后访问certsrv的问题
js 表格自动循环滚动,鼠标移入暂停
Fiddler download and installation